Vulnerability index

Browse CVEs

6,865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.5 CVE-2026-66431 Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-66441 Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-61978 Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-61984 Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-28186 Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.3 CVE-2026-28188 Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-28173 Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-28181 Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-28159 Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-27999 Subscriber Broken Access Control in Tourfic <= 2.23.1 versions. No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-27535 Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-27345 Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. No fix yet Fix from $4,9002026-08-13 HIGH 7.2 CVE-2026-6471 Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating… PostgreSQL No fix yet Fix from $4,9002026-08-13 MEDIUM 5.8 CVE-2026-73607 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authori… No fix yet Fix from $4,0002026-08-13 HIGH 8.6 CVE-2026-73608 SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authoriz… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.8 CVE-2026-73609 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in t… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-73603 Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatfl… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.8 CVE-2026-73605 SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesys… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-14332 The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-49819 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.5 CVE-2026-47718 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid… No fix yet Fix from $4,0002026-08-12 HIGH 7.6 CVE-2026-73326 CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72803 SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve blo… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72805 SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disc… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72806 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish pass… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72808 SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endp… No fix yet Fix from $4,0002026-08-12 HIGH 8.6 CVE-2026-72795 SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72796 SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass publish-access controls enforc… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72797 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint that returns encrypted noteb… No fix yet Fix from $4,0002026-08-12 HIGH 8.6 CVE-2026-72798 SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation … No fix yet Fix from $4,9002026-08-12